Web Application and Network Penetration Testing for a US Contract Services Company
Summary
A large US company providing contract security, transportation, and facility management services handles huge amounts of client information and must comply with SOC 2 and PCI DSS. To prepare for compliance audits, it engaged INNERLUXES to check its web applications, network, and employees' vigilance within two weeks. INNERLUXES performed gray-box penetration testing and a phishing campaign, found 14 high- and medium-severity issues, and — after remediation — confirmed a high security level by retest.
About the Customer
The Customer is a large US company that provides contract security, transportation, and facility management services.
The Challenge
Being a large company with several divisions, the Customer has a complex IT infrastructure that keeps growing and changing, creating a real security challenge for the in-house IT unit. The Customer handles huge amounts of client information and strives to ensure its confidentiality, integrity, and availability as required by SOC 2. As a service provider that accepts online payments, it must also comply with PCI DSS.
To prepare for PCI DSS and SOC 2 compliance audits, the Customer needed to check its web applications, network, and employees' vigilance to detect vulnerabilities that could lead to compliance breaches. It was looking for an independent expert security team to perform penetration and social-engineering testing within the shortest possible time — no more than two weeks.
The Solution
Considering the tight deadline and extensive testing scope, INNERLUXES's security experts proposed gray-box penetration testing. The Customer provided user credentials to examine exploitable vulnerabilities across the testing targets: 4 web applications, the external network perimeter, and the internal network. During the pentest, the team detected 14 security issues of high and medium severity, for example:
- Unlimited login attempts and no notification of multiple failed attempts, letting an attacker easily brute-force user account credentials.
- Remote file inclusion vulnerability. Any user could access the folder with write permissions on the Active Directory domain controller, download a payload, and use it to compromise domain security.
- Insecure session protection: missing the Secure and SameSite cookie attributes that help prevent man-in-the-middle attacks and cross-site request forgery.
- An administrator account on the domain controller with insecure configuration: no password expiration date, allowing attackers to brute-force the administrator password indefinitely and compromise the domain.
- Use of an inherently vulnerable Address Resolution Protocol (ARP). An intruder could perform an ARP spoofing attack to modify, disrupt, or spy on network traffic.
INNERLUXES evaluated the overall security level of the Customer's IT infrastructure as low and described the required corrective measures, such as:
- Limiting failed login attempts — when exceeded, blocking the user by IP or locking the account under attack for a few minutes, alerting the owner via email, and adding a CAPTCHA.
- Moving the folder with write permissions from the Active Directory domain controller to the file server.
- Applying the missing attributes that enhance cookie security.
- Enforcing password updates at least every 90 days; where possible, using complex passwords stored in a password manager and adding multi-factor authentication.
- Implementing network segmentation, enabling switch features that protect against ARP spoofing (Dynamic ARP Inspection, DHCP Snooping, Port Security), encrypting network traffic, and ensuring secure physical access to network devices.
With INNERLUXES's remediation guidance, the Customer's IT team fixed the revealed vulnerabilities, after which INNERLUXES retested the targets and confirmed that all the security issues endangering the Customer's sensitive data and IT infrastructure were properly remediated.
Phishing
Through open-source intelligence, INNERLUXES discovered 70 email addresses of the Customer's employees. Following the Customer's request to check its email security tools and employees' security awareness, the team first tried every possible scenario to bypass the email filtering system — and was glad to confirm it offered reliable protection against malicious emails. The Customer then whitelisted the testers' IPs so phishing emails could be delivered to the target employees. The social-engineering campaign proved a high level of user vigilance: none of the employees even opened the phishing emails.
However, the team found that several in-scope email addresses had been "pwned" — exposed in a previous data breach. INNERLUXES strongly recommended that those users thoroughly check their email settings and change the passwords for their accounts everywhere.
It took INNERLUXES 14 days to complete the project: plan and perform penetration and social-engineering testing, report on the results, and run another testing round to validate remediation.
The Results
- The Customer got a complete view of vulnerabilities in its applications and IT infrastructure.
- Applying the corrective measures, the Customer achieved a high security level for its IT environment.
- The phishing campaign proved the efficiency of the existing security awareness management strategy.
- The Customer received comprehensive project reports to complement its compliance documentation, helping it feel confident about the upcoming PCI DSS and SOC 2 audits.
Technologies and Tools
Metasploit, Wireshark, Nessus, Gophish, Wifite2, Burp Suite, Acunetix, Nmap, DirB.